High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-12490
CVE-2026-12490
Description
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versions
< 4.14.3-bp160.1.1+ 1 more
- (no CPE)range: < 4.14.3-bp160.1.1
- (no CPE)range: < 4.14.3-1.1
Patches
Vulnerability mechanics
References
1- www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txtnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.